ID

VAR-E-200905-0101


CVE

cve_id:CVE-2009-1729

Trust: 2.4

sources: BID: 34155 // PACKETSTORM: 77704 // EXPLOIT-DB: 32864 // EDBNET: 54371

EDB ID

32864


TITLE

Sun Java System Communications Express 6.3 - 'UWCMain' Cross-Site Scripting - Java webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 32864

DESCRIPTION

Sun Java System Communications Express 6.3 - 'UWCMain' Cross-Site Scripting. CVE-2009-1729CVE-54609 . webapps exploit for Java platform

Trust: 0.6

sources: EXPLOIT-DB: 32864

AFFECTED PRODUCTS

vendor:sunmodel:java system communications expressscope:eqversion:6.3

Trust: 1.9

vendor:sunmodel:java system communications express 2005q4scope: - version: -

Trust: 0.3

sources: BID: 34155 // EXPLOIT-DB: 32864 // EDBNET: 54371

EXPLOIT

source: https://www.securityfocus.com/bid/34155/info

Sun Java System Communications Express is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

This issue is tracked by Sun Alert ID 258068.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.

The following are vulnerable:

Sun Java System Communications Express 6.3 for Sun Java Communications Suite 5 and 6
Sun Java System Communications Express 6 2005Q4 (6.2)

http://www.example.com/uwc/base/UWCMain?anon=true&calid=test@test.com&caltype=temporaryCalids&date=20081223T143836Z&category=All&viewctx=day&temporaryCalendars=test@test.com%27;alert(%27hello%27);a=%27

Trust: 1.0

sources: EXPLOIT-DB: 32864

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 32864

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 32864

TYPE

'UWCMain' Cross-Site Scripting

Trust: 1.0

sources: EXPLOIT-DB: 32864

TAGS

tag:exploit

Trust: 0.5

tag:java

Trust: 0.5

tag:vulnerability

Trust: 0.5

tag:xss

Trust: 0.5

sources: PACKETSTORM: 77704

CREDITS

SCS team

Trust: 0.6

sources: EXPLOIT-DB: 32864

EXTERNAL IDS

db:NVDid:CVE-2009-1729

Trust: 2.4

db:EXPLOIT-DBid:32864

Trust: 1.9

db:BIDid:34155

Trust: 1.9

db:EDBNETid:54371

Trust: 0.6

db:PACKETSTORMid:77704

Trust: 0.5

sources: BID: 34155 // PACKETSTORM: 77704 // EXPLOIT-DB: 32864 // EDBNET: 54371

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2009-1729

Trust: 2.1

url:https://www.securityfocus.com/bid/34155/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/32864/

Trust: 0.6

url:http://www.coresecurity.com/content/sun-communications-express

Trust: 0.3

url:http://www.sun.com/software/products/calendar_srvr/comms_express/index.xml

Trust: 0.3

url:http://sunsolve.sun.com/search/document.do?assetkey=1-66-258068-1

Trust: 0.3

url:https://www.exploit-db.com/exploits/32864

Trust: 0.3

sources: BID: 34155 // PACKETSTORM: 77704 // EXPLOIT-DB: 32864 // EDBNET: 54371

SOURCES

db:BIDid:34155
db:PACKETSTORMid:77704
db:EXPLOIT-DBid:32864
db:EDBNETid:54371

LAST UPDATE DATE

2022-07-27T09:13:09.969000+00:00


SOURCES UPDATE DATE

db:BIDid:34155date:2009-05-21T16:20:00

SOURCES RELEASE DATE

db:BIDid:34155date:2009-05-20T00:00:00
db:PACKETSTORMid:77704date:2009-05-21T06:23:41
db:EXPLOIT-DBid:32864date:2009-05-20T00:00:00
db:EDBNETid:54371date:2009-05-20T00:00:00